Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
thw0rted
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
thw0rted
6y ago
Keep in mind, there's actual air-gapping, and there's secure enclaves. This specific attack would have no teeth if your Exchange server / OWA endpoint were only accessible from corporate VPN. You don't have to be one o
32.
▲
by
thw0rted
6y ago
There is a difference between being required to collect data that they wouldn't otherwise need for a legitimate business purpose, and being required to provide access to data they've already collected to their government. I'
33.
▲
by
thw0rted
6y ago
Here in Europe, Huawei and Xiaomi are two of the most popular phone brands I see in shops. Even if the government isn't actually buying them to issue as "work phones" for employees, those employees are certainly buying them
34.
▲
by
thw0rted
6y ago
If your design is "accidentally" indistinguishable from intentional state-sponsored surveillance, does it really matter whether you arrived at it through malice or incompetence?
35.
▲
by
thw0rted
6y ago
That's my point though, you don't get to survey people not buying the microtransaction because they quit due to terrible load times, whereas you could survey people who cancel a subscription. I guess they could still gather d
36.
▲
by
thw0rted
6y ago
I'm an Android user whose phone supports microSD. I never take the card out of my phone -- it's a PITA, requires an ejector tool I always manage to misplace, and I think I'm only supposed to do it with the phone powered off
37.
▲
by
thw0rted
6y ago
Seconded. I couldn't stand using a touchpad at all until I got a Surface Book 2 for work. It's now the standard to which I hold all other touchpads.
38.
▲
by
thw0rted
6y ago
I wonder if a paid subscription would have fixed this? If you left a paid MMO, they'd probably ask you to fill out an exit survey, and you could say "I'm canceling because load times are terrible", which would (hopefull
39.
▲
by
thw0rted
6y ago
This is probably good advice but not even relevant. It's down one level from the real problem: when your game spends 6 minutes on a loading screen, *profile* the process first. You can't optimize what you haven't measured.
40.
▲
by
thw0rted
6y ago
In another decade, there's going to be a story here about somebody getting their hands on the original source for this game, and the JSON parser will be a 10-line function with "//TODO: optimize later" at the top.
41.
▲
by
thw0rted
6y ago
I think you've got the right idea. It's about incentives. With fake positive reviews, the seller has an incentive to leave them up, and Amazon has no particular incentive to remove them -- you, a random user, has to somehow convi
42.
▲
by
thw0rted
6y ago
Just "prioritizing" doesn't fix it, you have to limit scoped packages to be provided by a single (trusted, internal) repo. Otherwise, what do you do when internal offers v1.2.3 but external says it has v1.99.99?
43.
▲
by
thw0rted
6y ago
There's even a security-versus-security tradeoff. If you manually review every dependency, are you also going to manually review every update to each of those dependencies? If you add friction to your update process, you're al
44.
▲
by
thw0rted
6y ago
I don't think it actually works this way for NPM specifically, if you're using scoped packages correctly. I believe you can associate a scope with one (private) repo and it will not fall back on the public repo, or choose newer
45.
▲
by
thw0rted
6y ago
I was confused by this aspect of the article. I have scoped, private packages in `@myscope`. I set up my `npmrc` with `@myscope:registry=url/to/my/private/repo`. I just checked, and if I try to install `@myscope/c
46.
▲
by
thw0rted
6y ago
I'm reading through all these responses and it sounds like nobody read the article. Everybody keeps bringing up JVM SecurityManager, or how granular Deno's permission system is, or a syntax for granting runtime permissions to mod
47.
▲
by
thw0rted
6y ago
I suspect that the author didn't want to eager-load all files because the API they're using is rate-limited -- 60 requests/hr when unauthenticated, or 5000/hr if you generate a unique OAuth token. Even that 5k could get
48.
▲
by
thw0rted
6y ago
I suspect it might be because the OP is about getting your account locked out, and several commenters have said that even paid accounts lose access to human support when they're locked out, so it's not actually a solution.
49.
▲
by
thw0rted
6y ago
Friendly reminder to anybody reading this with a Google account: it's not a perfect solution, but head over to Google Takeout and grab a dump of your account data while you're thinking of it. I did one last year, and at the same
50.
▲
by
thw0rted
6y ago
The OP is about a personal Google account, with access to mail, etc. at stake, but it's also about a developer who was going to create content for their platform. Granted, Stadia is not exactly a make-or-break gatekeeper for publishin
51.
▲
by
thw0rted
6y ago
Re-read the OP. No connection is actually made to `signal.tube`, it's only a placeholder domain for triggering an Android registered link handler so that it will open in their app.
52.
▲
by
thw0rted
6y ago
They're completely unrelated examples. I'll try to explain why. Iran's (authoritarian, human-rights-abusing) government wants to prevent citizens from communicating with each other using tools that are resistant to intercept
53.
▲
by
thw0rted
6y ago
At the risk of proving your point: why would I bother commenting if I didn't want to have a conversation? I'm either shouting into the void to hear my own figurative voice, or I think other people might actually be interested in
54.
▲
by
thw0rted
6y ago
I don't know if this question was asked before the question was asked upthread ("how do we know you won't cave to investor pressure to raise profits?", basically) but the answer was that they're chartered as a "
55.
▲
by
thw0rted
6y ago
See also: region locking in video games. Again, the development costs vastly outweigh the marginal cost of producing an extra unit to sell, so they sell the product at whatever the local market will bear, which breaks down if richer market
56.
▲
by
thw0rted
6y ago
It sounds like your team doesn't have a chat tool (Slack, Teams, etc), or if they do, they're using it wrong.
57.
▲
by
thw0rted
6y ago
This is a common trap that people fall in while trying to understand the problem. It's not that they chose the "wrong software", it's that they tried to scope every aspect of custom-designed software ahead of time. Im
58.
▲
by
thw0rted
6y ago
You can't just look at the clients, you have to consider a VPN protocol holistically. Do you think that most VPN installations are going to run two different gateways side-by-side so that they can provide Protocol X for Platforms A an
59.
▲
by
thw0rted
6y ago
Just because software is made available using a public web server does not mean that you are free to use it as you please. It's distributed along with a ToS agreement that governs its use. Bringing in words like "illegal" ca
60.
▲
by
thw0rted
6y ago
The reason is in the comment just below yours: Apple is a gatekeeper to ~40% of the US (last I checked, that number is low) and why bother writing an open-source tool if only half of your audience can use it? Especially if it's someth
More ›